# Cookie Policy

**Last updated: 1 October 2026**

LogiKFlow uses only the cookies and browser storage it needs to work. There are **no analytics, advertising or tracking cookies**, and nothing is shared with advertisers. Because every item below is strictly necessary, the Service doesn't show a cookie banner.

## Cookies

| Name | Purpose | Lasts |
|---|---|---|
| `__Host-prr_session` | Keeps you signed in. Holds a random token; only its hash is stored on our side. | 30 days, or until you sign out |
| `__Host-prr_oauth` | Protects GitHub sign-in against forgery (the OAuth `state` check) and remembers where to return. | 10 minutes |
| `__Host-oauth-consent-…` | Ties an AI agent's consent screen to your browser, so it can't be forged. | 10 minutes |
| `__Host-oauth-upstream-…` | Ties the GitHub sign-in step of an agent connection to your browser. | 10 minutes |

All of these are first-party, `Secure` and `HttpOnly`, which means page scripts can't read them.

Our hosting provider, Cloudflare, may set a strictly necessary security cookie such as `__cf_bm` to tell people from bots. See Cloudflare's cookie documentation for details.

## Browser storage

The Service saves a few display preferences in your browser's local storage. They never leave your device.

| Key | Purpose |
|---|---|
| `prr:mode` | Unified or split diff view |
| `prr:prefs` | Hide whitespace, compact line height, and whether the file tree is shown |

## Controlling cookies

You can clear or block cookies in your browser settings. If you block the session cookie, you won't be able to sign in.

## Contact

Questions: privacy@logikflow.dev

LogiKFlow is operated by ZikkLabs, Kerala, India.
